Apple is changing macOS Full Disk Access protections after concerns that AI agents could expose messages, files, browsing data, and other private content.

Apple says it will change macOS privacy settings to reduce the risk that third-party applications misuse Full Disk Access, a system-level permission that can expose files, mail, messages, browser data, and other information stored on a Mac.
The announcement follows a public dispute over whether Meta’s Muse AI assistant could access Apple Messages without a user explicitly enabling Muse’s Messages connector. Apple did not name Meta or Muse, and it has not said exactly how the permission changes will work or when they will arrive. But the timing places AI agents at the center of a broader debate over whether existing desktop permissions are adequate for software that can act across multiple applications.
For AI builders and enterprise buyers, the issue is larger than one assistant. Agents become more useful when they can inspect communications, calendars, files, and websites. The same access also creates a high-impact failure point if permissions are misunderstood, abused, or reached through another application running on the computer.
Apple said some developers are using Full Disk Access “in ways that could put users at risk,” according to the statement reported by Ars Technica. The company said those practices can expose entire systems, including files, mail, messages, and browsing history, without users fully understanding what they have authorized.
Apple also highlighted a second privacy concern: communication applications may expose information belonging not only to the person who installed the app, but also to colleagues, customers, friends, and other people whose messages appear in the account.
The company connected the risk directly to the growing capabilities of AI agents. As agents become more autonomous, Apple said, the consequences of granting broad system access could increase. Its stated goal is to help users understand the implications before approving the permission.
The available evidence does not identify a specific technical remedy. Apple has not disclosed whether it will add more granular controls, introduce new warnings, restrict access for particular categories of applications, or change how agents interact with protected data. The announcement therefore represents a policy and platform direction rather than a complete product specification.
The immediate controversy began after technology columnist Jason Aten reported receiving an unsolicited Muse notification that referenced an Apple Messages conversation with a co-worker. Aten said he had not knowingly granted Muse permission to read his messages and had assumed that content was unavailable to the assistant.
Meta CTO David Singleton responded that the Messages integration in the Muse Mac app was opt-in. Meta said Muse could read Messages content only when two conditions were met: macOS Full Disk Access had been granted and the Messages connector had been enabled.
That explanation was challenged by macOS security researcher Patrick Wardle. As summarized by Ars Technica, Wardle argued that Full Disk Access allows an application to read non-root files, including possible browser data, chats, and other locally stored information. His concern was that the underlying operating-system permission could be broader than the application-specific connector suggested.
The distinction matters for agent design. An application may present narrow, task-specific controls while holding an operating-system permission that technically reaches much more data. Users may understand that they enabled a connector, but not realize that another permission gives the application access to a wider local data store.
Meta’s public response, according to the report, repeated the opt-in explanation. The company did not provide a further response to questions from Ars Technica before publication. Apple also did not say that Muse caused the policy change.
The strongest confirmed fact is Apple’s statement that it intends to change Full Disk Access protections because some developers may be using the permission in ways that put users at risk. The company’s comments establish the platform concern, but not a specific finding against Meta or any other named developer.
Ars Technica reported that there were no known reports of other applications abusing Full Disk Access to read messages and browsing history. The publication also noted that Apple’s announcement could be unrelated to the Muse incident, although its timing makes a connection plausible.
The episode follows another security concern involving Muse. Wardle reportedly disclosed a configuration that allowed any application or code running on a Mac to take control of the assistant. Ars Technica said this could include commands injected through ClickFix attacks, a category of social-engineering attack that tricks users into executing malicious instructions. An attacker who gained that control could potentially access resources available to Muse.
Amazon has also blocked Muse from its platform, saying applications of this kind should operate openly and respect service providers’ decisions about whether to participate. That action is a separate platform-policy dispute, not evidence that Apple’s permission system has been compromised.
Taken together, the reports indicate growing scrutiny of Muse’s access model. They do not establish how often users have enabled the relevant settings, how much data Muse has accessed, or whether any confirmed breach occurred. Adoption, safety, and performance conclusions should therefore be treated cautiously.
For AI developers, Apple’s announcement raises the cost of relying on broad desktop permissions as a shortcut to integration. An agent that reads local databases, message stores, browser sessions, or application files can offer a smoother experience, but it also inherits the security and privacy weaknesses of every accessible data source.
Builders may need to favor narrower connectors, explicit per-source authorization, stronger audit logs, and clearer explanations of what an agent can read and do. Those controls are especially important when an agent can both retrieve information and take actions, such as sending messages, changing records, or following instructions found in untrusted content.
Enterprise teams should treat Full Disk Access as a high-risk privilege rather than a routine installation step. Device-management policies may need to restrict which applications can receive it, while security teams should monitor for unexpected access to message stores, browser data, and sensitive files. The practical question is not only whether an agent is useful, but whether its permissions can be limited, revoked, and investigated.
Apple’s move could also pressure AI companies to separate product features from operating-system privileges more carefully. If a Messages connector requires full-disk access, developers may face demands to explain why and to prove that the permission is necessary. That could slow deployment, but it may also create clearer boundaries between an agent’s intended workflow and the data it can technically reach.
The most important follow-up is Apple’s technical specification. Watch for whether the company introduces scoped access, new consent screens, application entitlements, or restrictions on how Full Disk Access can be used by AI agents and other communication tools.
Developers and security teams should also look for changes in Muse’s permissions model, clearer documentation from Meta, and any independent testing of the assistant’s Messages integration. A confirmed account of what data Muse can access under different combinations of macOS and in-app settings would be more useful than broad assurances about opt-in controls.
Further signals will include enterprise-management support, Apple’s handling of legacy applications, and whether other operating-system vendors adopt more granular controls for agentic software. The market is likely to reward agents that can demonstrate least-privilege access without sacrificing core workflows.
Apple’s announcement reflects a mismatch between traditional desktop permissions and modern AI agents. Full Disk Access was already powerful, but an agent can turn that permission into a continuously usable interface across messages, files, browsers, and business systems. A setting that once looked like a technical installation detail now affects an agent’s effective operating boundary.
The key test will be implementation, not the warning itself. Builders need permission systems that users can understand and administrators can govern, while enterprises need evidence that an agent can be useful without receiving unrestricted access to an entire device. Until Apple publishes the mechanics, the safest conclusion is that broad local access remains a material risk for AI agents, even when an application describes individual integrations as optional.